Trending...
- Polis Administration Announces Return of Popular Colorado E-Bike Rebates
- Heritage at South Brunswick Introduces New Ferndale Floorplan: The Largest Single-Family Home Design in the Community
- Portalz Publishes FES World First Architecture Introducing a New Cryptographic Platform
Research introduces a deterministic, auditable pipeline that reconstructs control flow and Metro modules, validated by round-trip re-execution across 11 compiler versions.
BROOKLYN, N.Y. - ColoradoDesk -- Symbiotic Security today announced new research and an open-source tool for deterministic decompilation of Hermes bytecode, the format used by React Native applications in production builds. The decompiler recovers readable JavaScript, including structured control flow, module boundaries, and identifiers, with deterministic output designed for security review.
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Colorado Desk
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
Find the full research paper here https://hubs.ly/Q04pLtpM0
The research reports coverage across 60 Hermes bytecode versions (HBC 40 to 99) and validation via a public round-trip corpus that recompiles and re-executes decompiled programs across 11 compiler versions, with all 359 programs producing identical output.
"Security reviewers need output they can audit," said a security researcher at Symbiotic Security. "We built a deterministic pipeline so the same bundle yields the same output and every construct can be traced back to the binary."
More on Colorado Desk
- 303 Crown Maids Unveils New Dedicated Boulder Page for Transparent, Instant Online House Cleaning
- Purgatory Resort to Host Mountain States Cup Series Finale
- Michael Maertens Hired as Century Fasteners Corp. – Chief Financial Officer
- Built to Last: Why BSI Is Among the Nation's Fastest-Growing Companies, and One of Its Best Places to Work
- Boulder SEO Marketing Takes a Denver EdTech SaaS From Invisible to AI-Cited, Growing Form Fills 401%
The tool which can be accessed here https://github.com/SymbioticSec/hermes-decomp has been used in penetration testing and capture-the-flag challenges, helping reviewers reach relevant code paths in large bundles.
About the research
The research addresses a long-standing gap in mobile app security review. Most React Native apps ship their JavaScript compiled into Hermes bytecode, a compact binary format that strips out variable names and file boundaries, leaving security reviewers with raw instructions instead of readable code. Symbiotic Security's decompiler reconstructs that code: it rebuilds loops and conditionals, restores the original module structure, and recovers function names directly from the binary while clearly flagging any names it infers.
Because the approach is rule-based rather than AI-generated, the same app always produces the same output, and every line can be traced back to the binary, a property security audits depend on.
The tool spans 60 bytecode versions (React Native releases from 2019 to 2026) and is validated by a public test suite of 359 programs that all re-execute identically.
Resources
- Research paper download: https://hubs.ly/Q04pLtpM0
- GitHub repository: https://hubs.ly/Q04q0SwP0
Source: Symbiotic Security
0 Comments
Latest on Colorado Desk
- PricZone Launches Online Shopping Platform Offering Electronics, Gaming, and More
- Colorado Springs: Wooten Road south of Galley Road to close Aug. 10 for culvert improvements
- Colorado Springs: Work resumes Monday on 8th Street Bridge over Fountain Creek
- Heritage at South Brunswick Introduces New Ferndale Floorplan: The Largest Single-Family Home Design in the Community
- Q&A with Homegrown Sporting Goods president Jim Zetts
- Lineus Medical Elevates Leadership to Accelerate Growth After Breakthrough Clinical Results
- Gateway Center Arena Announces Duane Curry as General Manger
- Kaufman & Kaufman, LLC Highlights Importance of Preventing and Reporting Summer Workplace Injuries
- 7th Annual Palmer Lake Wine Festival Celebrates Colorado Wine to Meet Nonprofit Partner's Needs
- Governor Polis Verbally Declares Disaster Emergency for 310 Fire, Provides Update on Status of Wildfires and Floods in Colorado
- XRPPower Expands Platform Security With Enhanced Brand Protection and Official Verification Standards
- Cuvo Health, the #1 White Label Telehealth Platform, Surpasses 300 Exclusive Providers Serving All 50 States
- RAS AP Consulting Expands Managed AP Governance™ Ecosystem, Launches Trademark Process, and Secures IFOL Speaker Invitation
- UK Financial Ltd Makes History: Chainlink CRE Circulating Supply Verification Goes Live Across Its Complete Ecosystem Of Nine Exchange-Traded Tokens
- International Rights Groups Raise Alarm Over Freedom of Religion and Expression in South Korea
- Colorado: Governor Polis Appoints M. Christina Floyd to the Lake County Court and Jeffrey M. Cure to the Kit Carson County Court
- Strengthening Colorado's Economy: What They're Saying About Action to Make Permitting Easier in Colorado
- The City's Most Elegant Open-Air Dinner Party Returns September 12, 2026
- FDA Clears Major Regulatory Hurdle as Preservative-Free Ketamine Program Moves Within Reach of Commercialization: NRx Pharmaceuticals: (NAS DAQ: NRXP)
- Autonomous Robotics Platform Expansion as Public Market Debut is Very Close: MBody AI Corp. (N A S D A Q: MBAI)
